-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 18 Jul 2020 21:11:58 +0200 Source: ruby-sanitize Architecture: source Version: 4.6.6-2.1~deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 963808 Changes: ruby-sanitize (4.6.6-2.1~deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Rebuild for buster-security . ruby-sanitize (4.6.6-2.1) unstable; urgency=medium . * Non-maintainer upload. * fix: Don't treat :remove_contents as `true` when it's an Array * feat: Remove useless filtered element content by default * Fix sanitization bypass in HTML foreign content (CVE-2020-4054) (Closes: #963808) Checksums-Sha1: 772273b36cb7d3d78ee631b055ebc43791d6e790 2330 ruby-sanitize_4.6.6-2.1~deb10u1.dsc e660c44ac13c945d43598eaf3a6f4f68c0b472ec 40115 ruby-sanitize_4.6.6.orig.tar.gz a517ab73882ea7b83d28332b8456d4360eadebb5 7544 ruby-sanitize_4.6.6-2.1~deb10u1.debian.tar.xz ef1cafe55724a0534b70fc6729cef180ebdfb39c 7210 ruby-sanitize_4.6.6-2.1~deb10u1_source.buildinfo Checksums-Sha256: ce8d93ebff76b7c9c78d033a97d197e809985a671886259f5ccd01ce2152096b 2330 ruby-sanitize_4.6.6-2.1~deb10u1.dsc 5d5b72076d13b731638e6189a83988237a47ab4d8ce6bfa5aded31ec0f333238 40115 ruby-sanitize_4.6.6.orig.tar.gz 9fdecb0203bcf3eddfb8a40c010e4025458821fca4e66f31779dd25b3ad3b94a 7544 ruby-sanitize_4.6.6-2.1~deb10u1.debian.tar.xz 5d26c6dcf630ff9e4d5ae62c8d267155e5a605fa43ead3cc1c8994c8e2840864 7210 ruby-sanitize_4.6.6-2.1~deb10u1_source.buildinfo Files: b3c812b64b39fb5f586d41ef59724652 2330 ruby optional ruby-sanitize_4.6.6-2.1~deb10u1.dsc aa34226fdbfd69430ae83aabbb8d894a 40115 ruby optional ruby-sanitize_4.6.6.orig.tar.gz 0a92404b1cd28519c525de9ad4b3e8ee 7544 ruby optional ruby-sanitize_4.6.6-2.1~deb10u1.debian.tar.xz 06972bf224c633df58d9a10fe3848ea0 7210 ruby optional ruby-sanitize_4.6.6-2.1~deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl8TSeVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EuBIP/j2+xttQ4KzuB5S4gmtpoHeEp+WUwiRU 9AZMZCz57bb1UI2IoTG0d6wIktUHUDrGaSkNlEsSthl8iZpyp8HHfYopWJkFD+rZ BbmCqO7coFXe65fqhbxMpIr9CDjNVuEkeH5WQAfcKNpSJoLMbzViY1kHvF0Veq/r qiVle/aICCzLWVJpthkzfPv+5vfF679c/H9zZcqsTEdXRsQ20BearRH4MX98cQCe BBkLRFcmwf9dM91LANy9zgAH9N+CxLt6KymQtfxPnu2HwOyUuQXPS1woutEADzXt IiSZhCUrCgQNJLE1uEG58hcNs7nq90BwO2lZG1zfbjuW5lFABIFLxrN9KTy6pfdf BU0ZqdNOcD4/omjpjyJBudJ3uKAmp5qnmICj/PUrwQmYlcIrWlmzvBKjhumF7ftA YNnIirdDbQ3VDjG4vIG76dRV5d3qrNR8fH3czAzqJyfFl1kAm77zMjBY+dFzS7vc IHm2tYYY7f0kcVnYLoptdNFQ53EJcLPf9RTnfITU2csfyTJ6DRQM4znT/pb3mbAU YaUpWT/Ys9rNP0jVqh7veeNCt+0RU9nHbM9lf0aG1DsSrkbYB7xP3js3h95A2izw ZGHtc3xmS1QeXlzN8KcjXLnA63NCh7+YKc2Z3ZB2BsG5YHiTwUs8fqqFUCxaKcqj 4mf0OcOmJgc/ =rhQc -----END PGP SIGNATURE-----